Hello
I have a TP-Link router that is on LEDE 17 with the following port configuration
Switch Ports:
0 eth1
1 WAN
2 LAN1
3 LAN2
4 LAN3
5 LAN4
6 eth0
The default config for /etc/config/network for the vlan is
network
config switch_vlan
option device 'switch0'
option vlan '1'
option vid '1'
option ports '0 2 3 4 5'
config switch_vlan
option device 'switch0'
option vlan '2'
option vid '2'
option ports '1 6'
What I want to do (have already done it just need confirmation settings are correct) is separate ports 4 and 5 so they only have access to internet but not to internal network (ports 2, 3 and wifi) so this is what I did
/etc/config/network *note: I dont know if for vlan 1 and 2 if port 0 needs to be tagged
network
config interface 'lan'
option type 'bridge'
option proto 'static'
option ipaddr 'x.x.1.1'
option netmask '255.255.255.0'
option ip6assign '60'
option ifname 'eth1.1'
config interface 'lan2'
option proto 'static'
option ipaddr 'x.x.2.1'
option netmask '255.255.255.0'
option ip6assign '60'
option ifname 'eth1.2'
config switch
option name 'switch0'
option reset '1'
option enable_vlan '1'
config switch_vlan
option device 'switch0'
option vlan '1'
option vid '1'
option ports '0t 2 3'
config switch_vlan
option device 'switch0'
option vlan '2'
option vid '2'
option ports '0t 4 5'
config switch_vlan
option device 'switch0'
option vlan '3'
option ports '1 6'
option vid '3'
On /etc/config/dhcp
dhcp
config dhcp 'lan'
option interface 'lan'
option start '100'
option limit '150'
option leasetime '12h'
config dhcp 'lan2'
option interface 'lan2'
option start '100'
option limit '150'
option leasetime '12h'
On /etc/config/firewall *note: I noticed that I needed to set for LAN2 the input to REJECT otherwise if it was set to ACCEPT (input) I could ping between VLAN, can someone confirm I want REJECT
*Note 2: I noticed that if I set input to REJECT then I would not get a DHCP address so I added so config rules (found at the bottom of firewall) for DNS and DHCP, is this necesarry?
*Note 3: I noticed that I also needed to add config forwarding between LAN2 to WAN otherwise there was no internet, is this correct?
firewall
config zone
option name 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
option network 'lan'
config zone
option name 'lan2'
option network 'lan2'
option output 'ACCEPT'
option forward 'REJECT'
option input 'REJECT'
config forwarding
option dest 'wan'
option src 'lan2'
config rule
option target 'ACCEPT'
option proto 'tcp udp'
option dest_port '53'
option src 'lan2'
option name 'lan2 DNS'
option family 'ipv4'
config rule
option enabled '1'
option target 'ACCEPT'
option proto 'udp'
option dest_port '67-68'
option family 'ipv4'
option src 'lan2'
option name 'lan2 DHCP'
Can someone confirm I have set it all correctly
thanks